Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 54 pages
Exam (elaborations)

PCI ISA Exam 200 Questions and Correct Answers.

Document preview thumbnail
Preview 4 out of 54 pages

PCI ISA Exam 200 Questions and Correct Answers.

Content preview

PCI ISA Exam 200 Questions and Correct Answers
1: What is the primary purpose of the PCI DSS?

A. To regulate credit card interest rates
B. To protect cardholder data and reduce payment card fraud
C. To mandate specific security products
D. To replace national data protection laws

CORRECT ANSWER: B. To protect cardholder data and reduce payment card fraud

Rationale: The Payment Card Industry Data Security Standard (PCI DSS) was developed to
enhance payment account security and reduce fraud by establishing baseline security controls
for entities that store, process, or transmit cardholder data.

2: Which entities are required to comply with PCI DSS?

A. Only large merchants
B. Only payment processors
C. Any entity that stores, processes, or transmits cardholder data
D. Only banks

CORRECT ANSWER: C. Any entity that stores, processes, or transmits cardholder data

Rationale: PCI DSS applies to all entities—merchants, service providers, processors, and
financial institutions—that handle cardholder data, regardless of size or transaction volume.

3: What does "cardholder data" (CHD) include under PCI DSS?

A. Only the primary account number (PAN)
B. PAN plus cardholder name, expiration date, and/or service code
C. Only sensitive authentication data
D. Only tokenized data

CORRECT ANSWER: B. PAN plus cardholder name, expiration date, and/or service code

Rationale: Cardholder data includes the Primary Account Number (PAN) and may include
cardholder name, expiration date, and/or service code when stored with the PAN. Sensitive
authentication data (full track data, CAV2/CVC2/CVV2/CID, PINs) must never be stored post-
authorization.

4: Which PCI DSS requirement addresses network security controls?

,A. Requirement 1
B. Requirement 3
C. Requirement 8
D. Requirement 12

CORRECT ANSWER: A. Requirement 1

Rationale: Requirement 1 focuses on installing and maintaining network security controls,
including firewalls, to protect the cardholder data environment (CDE).

5: What is the minimum frequency for reviewing firewall rule sets per PCI DSS?

A. Monthly
B. Quarterly
C. Every 6 months
D. Annually

CORRECT ANSWER: C. Every 6 months

Rationale: PCI DSS Requirement 1.2.2 requires firewall rule sets to be reviewed at least every six
months to ensure they remain necessary and appropriate.

6: Which of the following is considered sensitive authentication data that must NOT be stored
post-authorization?

A. Cardholder name
B. Primary Account Number (PAN)
C. Full track data
D. Expiration date

CORRECT ANSWER: C. Full track data

Rationale: Full track data (from the magnetic stripe or chip equivalent) is sensitive
authentication data that must never be stored after authorization, per PCI DSS Requirement 3.2.

7: What is the primary purpose of segmentation in PCI DSS compliance?

A. To reduce network costs
B. To isolate the cardholder data environment from other networks
C. To increase internet speed
D. To simplify user access

CORRECT ANSWER: B. To isolate the cardholder data environment from other networks

,Rationale: Segmentation reduces the scope of PCI DSS by isolating systems that store, process,
or transmit cardholder data from other network segments, limiting the systems subject to
assessment.

8: Which encryption standard is commonly accepted for protecting stored cardholder data?

A. DES
B. AES with strong key management
C. ROT13
D. Base64 encoding

CORRECT ANSWER: B. AES with strong key management

Rationale: PCI DSS Requirement 3.5 requires strong cryptography (e.g., AES) with robust key
management practices to protect stored cardholder data. Weak algorithms like DES are not
acceptable.

9: What is the minimum key strength required for RSA encryption under PCI DSS?

A. 512 bits
B. 1024 bits
C. 2048 bits or higher
D. No minimum

CORRECT ANSWER: C. 2048 bits or higher

Rationale: PCI DSS requires cryptographic keys to be strong; for RSA, keys must be at least 2048
bits to be considered strong cryptography.

10: Which PCI DSS requirement addresses access control?

A. Requirement 2
B. Requirement 5
C. Requirement 7
D. Requirement 10

CORRECT ANSWER: C. Requirement 7

Rationale: Requirement 7 focuses on restricting access to cardholder data by business need-to-
know, implementing role-based access controls.

11: What is the purpose of unique IDs for personnel with computer access?

A. To simplify login
B. To enable accountability and traceability of actions

, C. To reduce password complexity
D. To allow shared accounts

CORRECT ANSWER: B. To enable accountability and traceability of actions

Rationale: PCI DSS Requirement 8.1 requires unique IDs to ensure actions can be traced to
individual users, supporting accountability and forensic investigations.

12: How often must user access rights be reviewed per PCI DSS?

A. Weekly
B. Monthly
C. At least quarterly
D. Annually

CORRECT ANSWER: C. At least quarterly

Rationale: Requirement 7.2.3 requires user access rights to be reviewed at least quarterly to
ensure access remains appropriate and necessary.

13: Which authentication factor is considered "something you have"?

A. Password
B. Fingerprint
C. Smart card or token
D. PIN

CORRECT ANSWER: C. Smart card or token

Rationale: Multi-factor authentication requires at least two of: something you know (password),
something you have (token), or something you are (biometric). Smart cards/tokens represent
"something you have."

14: What is the minimum password complexity required by PCI DSS?

A. 6 characters, any type
B. 7 characters with numeric only
C. At least 7 characters with numeric and alphabetic
D. No requirements

CORRECT ANSWER: C. At least 7 characters with numeric and alphabetic

Rationale: PCI DSS Requirement 8.3.6 requires passwords/passphrases to be at least 7
characters long and contain both numeric and alphabetic characters (or equivalent complexity).

15: Which PCI DSS requirement addresses malware protection?

Document information

Uploaded on
March 24, 2026
Number of pages
54
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$22.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
TutorExpert
3.7
(76)
Sold
572
Followers
314
Items
10386
Last sold
1 day ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions